First published: Wed Jul 31 2019(Updated: )
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=3.5.0<=3.5.6 | 3.5.7 |
composer/moodle/moodle | =3.7.0 | 3.7.1 |
composer/moodle/moodle | >=3.6.0<=3.6.4 | 3.6.5 |
Moodle | <3.5.7 | |
Moodle | >=3.6.0<3.6.5 | |
Moodle | >=3.7.0<3.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10186 has a medium severity level due to the potential for CSRF attacks through the XML loading/unloading admin tool.
To fix CVE-2019-10186, upgrade Moodle to version 3.5.7 or later, or 3.6.5 or later, or 3.7.1 or later.
Versions of Moodle affected by CVE-2019-10186 are 3.5.0 to 3.5.6, 3.6.0 to 3.6.4, and 3.7.0 to 3.7.0.
CVE-2019-10186 is a Cross-Site Request Forgery (CSRF) vulnerability due to the absence of a sesskey token.
Administrators of Moodle instances using the affected versions are at risk from CVE-2019-10186.